2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-26200MEDIUM6.8A component of Kaspersky custom boot loader allowed loading of untrusted UEFI modules due to insufficient check of their...
CVE-2020-24455MEDIUM6.7Missing initialization of a variable in the TPM2 source may allow a privileged user to potentially enable an escalation ...
CVE-2020-4931MEDIUM6.5IBM MQ 9.1 LTS, 9.2 LTS, and 9.1 CD AMQP Channels could allow an authenticated user to cause a denial of service due to ...
CVE-2020-12702MEDIUM4.6Weak encryption in the Quick Pairing mode in the eWeLink mobile application (Android application V4.9.2 and earlier, iOS...
CVE-2020-8297MEDIUM4.3Nextcloud Deck before 1.0.2 suffers from an insecure direct object reference (IDOR) vulnerability that permits users wit...
CVE-2020-7120MEDIUM5.3A local authenticated buffer overflow vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior t...
CVE-2020-26609MEDIUM5.4fastadmin V1.0.0.20200506_beta contains a cross-site scripting (XSS) vulnerability which may allow an attacker to obtain...
CVE-2020-4953MEDIUM4.3IBM Planning Analytics 2.0 could allow a remote authenticated attacker to obtain information about an organization's int...
CVE-2020-8902MEDIUM4.3Rendertron versions prior to 3.0.0 are are susceptible to a Server-Side Request Forgery (SSRF) attack. An attacker can u...
CVE-2020-13697MEDIUM6.1An issue was discovered in RouterNanoHTTPD.java in NanoHTTPD through 2.3.1. The GeneralHandler class implements a basic ...
CVE-2020-29075MEDIUM6.5Acrobat Reader DC versions 2020.013.20066 (and earlier), 2020.001.30010 (and earlier) and 2017.011.30180 (and earlier) a...
CVE-2020-27819MEDIUM5.5An issue was discovered in libxls before and including 1.6.1 when reading Microsoft Excel files. A NULL pointer derefere...
CVE-2020-35852MEDIUM6.1Chatbox is affected by cross-site scripting (XSS). An attacker has to upload any XSS payload with SVG, XML file in Chatb...
CVE-2020-36232MEDIUM5The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37, from version 4.3.0 before 4.3.14, from vers...
CVE-2020-29453MEDIUM5.3The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.11, from 8.6.0 befor...
CVE-2020-29448MEDIUM5.3The ConfluenceResourceDownloadRewriteRule class in Confluence Server and Confluence Data Center before version 6.13.18, ...
CVE-2020-22475MEDIUM6.8"Tasks" application version before 9.7.3 is affected by insecure permissions. The VoiceCommandActivity application compo...
CVE-2020-22474MEDIUM6.5In webERP 4.15, the ManualContents.php file allows users to specify the "Language" parameter, which can lead to local fi...
CVE-2020-19762MEDIUM6.1Automated Logic Corporation (ALC) WebCTRL System 6.5 and prior allows remote attackers to execute any JavaScript code vi...
CVE-2020-3664MEDIUM6Out of bound read access in hypervisor due to an invalid read access attempt by passing invalid addresses in Snapdragon ...
CVE-2020-11286MEDIUM6.8An Untrusted Pointer Dereference can occur while doing USB control transfers, if multiple requests of different standard...
CVE-2020-11198MEDIUM6.7Key material used for TZ diag buffer encryption and other data related to log buffer is not wiped securely due to improp...
CVE-2020-11147MEDIUM6.7Use after free issue in audio modules while removing and freeing objects during list iteration due to incorrect usage of...
CVE-2020-35664MEDIUM6.1An issue was discovered in Acronis Cyber Protect before 15 Update 1 build 26172. There is cross-site scripting (XSS) in ...
CVE-2020-35571MEDIUM6.1An issue was discovered in MantisBT through 2.24.3. In the helper_ensure_confirmed call in manage_custom_field_update.ph...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now